Security News > 2020 > January > Hanna Andersson Data Breach: Hackers Compromise Website of Children's Clothier

Portland, Oregon-based children's clothing maker Hanna Andersson has quietly disclosed a breach to affected customers.
According to the breach notification letter, the "Incident potentially involved information submitted during the final purchase process on our website, www.hannaandersson.com, including name, shipping address, billing address, payment card number, CVV code, and expiration date." These details are often known on the dark web as 'fullz'; that is, the data contains all the information necessary for a criminal to make fraudulent purchases via the internet.
The Hannah Andersson breach has not been confirmed as a Magecart attack, but such attacks generally involve the insertion of malicious skimmer code into the victim company's payment code.
Hanna Andersson is providing no details of the attack.
"We can definitively state," says the Verizon 2019 Payment Security Report, "We have never reviewed an environment or investigated a PCI data breach involving an affected entity that was truly PCI DSS compliant." Coincidentally, this report was published at the very end of the Hanna Andersson breach.
News URL
Related news
- Largest US addiction treatment provider notifies patients of data breach (source)
- STIIIZY data breach exposes cannabis buyers’ IDs and purchases (source)
- EU law enforcement training agency data breach: Data of 97,000 individuals compromised (source)
- Wolf Haldenstein law firm says 3.5 million impacted by data breach (source)
- Otelier data breach exposes info, hotel reservations of millions (source)
- HPE investigates breach as hacker claims to steal source code (source)
- CISA: Hackers still exploiting older Ivanti bugs to breach networks (source)
- PayPal to pay $2 million settlement over 2022 data breach (source)
- UnitedHealth now says 190 million impacted by 2024 data breach (source)
- PowerSchool starts notifying victims of massive data breach (source)